Unauthenticated Configuration Switching Vulnerability in Innomic Products
CVE-2022-50980

6.5MEDIUM

What is CVE-2022-50980?

A vulnerability exists in Innomic products allowing an unauthenticated adjacent attacker to disrupt operations by switching between multiple configuration presets via the Controller Area Network (CAN). This could lead to instability and operational disruptions, making it essential for users to assess their system's configuration settings and implement necessary security measures.

Affected Version(s)

AvibiaLine AVLX1 HD 5.0 2.1.1340 <= 2.1.1387

AvibiaLine AVLX1 HD 5.0 2.1.1866

AvibiaLine AVLX2 HD 5.0 2.1.1340 <= 2.1.1387

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.